We use cookies to provide you with a better experience. By continuing to browse the site you are agreeing to our use of cookies in accordance with our Cookie Policy.
  • INDUSTRY PRESS ROOM
  • ABOUT
  • CONTACT
  • MEDIA FILE
  • Create Account
  • Sign In
  • Sign Out
  • My Account
Free Newsletters
  • MAGAZINE
    • Current Issue
    • Archives
    • Digital Edition
    • Subscribe
    • Newsletters
    • Mobile Apps
  • TRANSPORTATION
  • MATERIAL HANDLING
  • TECHNOLOGY
  • LIFT TRUCKS
  • PODCAST ETC
    • Podcast
    • Webcasts
    • Blogs
      • One-Off Sound Off
      • Global Logistics and Risk
      • Empowering Your Performance Edge
      • Analytics & Big Data
      • Submit your blog post
    • Events
    • White Papers
    • Industry Press Room
      • Upload Your News
    • New Products
      • Upload Your Product News
    • Conference Guides
    • Conference Reports
    • Newsletters
    • Mobile Apps
  • DCV-TV
    • DCV-TV 1: News
    • DCV-TV 2: Case Studies
    • DCV-TV 3: Webcasts
    • DCV-TV 4: Viewer Contributed
    • DCV-TV 5: Solution Profiles
    • Parcel Forum 2022
    • MODEX 2022
    • Upload Your Video
  • MAGAZINE
    • Current Issue
    • Archives
    • Digital Edition
    • Subscribe
    • Newsletters
    • Mobile Apps
  • TRANSPORTATION
  • MATERIAL HANDLING
  • TECHNOLOGY
  • LIFT TRUCKS
  • PODCAST ETC
    • Podcast
    • Webcasts
    • Blogs
      • One-Off Sound Off
      • Global Logistics and Risk
      • Empowering Your Performance Edge
      • Analytics & Big Data
      • Submit your blog post
    • Events
    • White Papers
    • Industry Press Room
      • Upload Your News
    • New Products
      • Upload Your Product News
    • Conference Guides
    • Conference Reports
    • Newsletters
    • Mobile Apps
  • DCV-TV
    • DCV-TV 1: News
    • DCV-TV 2: Case Studies
    • DCV-TV 3: Webcasts
    • DCV-TV 4: Viewer Contributed
    • DCV-TV 5: Solution Profiles
    • Parcel Forum 2022
    • MODEX 2022
    • Upload Your Video
Home » Supply chain looks to cyber self-defense
CYBER SECURITY

Supply chain looks to cyber self-defense

Hackers are targeting transportation firms as the industry embraces digitalization, the IoT, and smartphone apps. But there are protective steps these firms can take, experts say.

Padlock in cyberspace
June 12, 2020
Ben Ames
No Comments

Computer hackers loom large in newspaper headlines and Hollywood movies, but transportation and supply chain workers haven’t traditionally seen them as a real threat. After all, driving a truck or a forklift meant you were seldom even near a computer keyboard, and there’s nothing digital about booking freight loads using a clipboard and a phone.

However, in the past five years, the logistics industry has been awash in cybertrends like supply chain digitalization, the Internet of Things (IoT), and the expanded use of electronic logging devices (ELDs), not to mention the smartphones that most Americans carry in their pockets or purses these days.

Hackers have taken notice, and in recent months, they’ve rung up a string of successful attacks on supply chain stalwarts such as the digital freight broker truckstop.com, ocean carrier Mediterranean Shipping Co. (MSC), freight brokerage Total Quality Logistics (TQL), Australian third-party logistics services provider Toll Group, and transportation provider Roadrunner Transportation Systems Inc.

Most of those attacks used “ransomware” to lock down the victims’ computer networks, hobbling their logistics operations until they cracked the code or paid a ransom to the data-kidnappers. As a rule, the targets of these cybercriminals do not disclose the details of the extortion to avoid encouraging future attacks.

The financial damage aside, the mere act of freezing a company’s operations for a few days can damage the victim’s reputation. Even the names of the bugs and viruses deployed by hackers sound frightening, including malware like Azorult, Hawkeye, Kwampirs, Locky, Lokibot, Nanocore, Netwired, Remcos, and Shamoon.

Despite the growing danger posed by cyberthreats, logistics firms can follow some basic rules to greatly reduce their exposure, such as educating employees, putting proper network controls in place, and creating disaster recovery plans.

PROTECT THE WEAKEST LINK

One way companies can protect themselves is by defining a single set of best practices for all employees, regardless of their role in the organization, says Chris Sandberg, vice president of information security for supply chain technology company Trimble Transportation.

Trimble, a provider of fleet management and transportation management software, says many of its clients rely on a compex IT (information technology) infrastructure in their daily operations, noting that a typical logistics service provider might have servers in its back office, telematics hardware on its trucks, and cloud-based networks used to manage maintenance and other critical tasks. “It’s important to have that standard so the same … controls are in place across all the different [types] of technology a customer might be using, because a chain is only as strong as its weakest link,” Sandberg says.

Another critical step in cyber self-defense is to establish a recovery plan before a problem ever develops. “The best time to develop your disaster plan is not during the disaster,” Sandberg says. “If you’re a trucking company and you get stuck with a crypto-lock virus, how do you continue operations? If you’ve identified certain elements as critical resources, you can come up with mitigation strategies.”

As logical as that might sound, smaller carriers often lack the resources to prepare disaster recovery plans ahead of time, Sandberg says. On top of that, they frequently lack the IT capabilities to distinguish between “white hat” hackers—who are basically using their skills to help companies identify their digital vulnerabilities—and “black hat” hackers who are plotting serious crimes, Sandberg says. A cybercriminal looking for a big payout might threaten a company by freezing its data and demanding a ransom, by stealing and selling a company’s data, or by collecting demographic information on its employees in an attempt to hire them away.

In many cases, an employee won’t even realize that they’ve become the victim of a hack until it’s too late, he says. “If someone sends out an email with malware links, they’re not targeting someone; it’s indiscriminate. They’re just trying to get someone to click on the link so they can freeze the account and get them to pay a ransom,” he says.

In another approach, a hacker might target truck drivers by offering them a free smartphone app that provides discounts on food and fuel, for example. That sounds harmless at first, but all data has value, Sandberg says. “Most people don’t read the disclaimers before they download an app,” he says. “Then, the hacker can scrape demographic information from them [and share it with] competing carriers. With the driver shortage, those carriers could use that information to target their advertising to a specific population of drivers and hire away those employees.”

For operations facing such threats, the best defense is education, says Jane Jazrawy, CEO of CarriersEdge, a provider of online driver-training platforms. And that’s become particularly important since the onset of the Covid-19 pandemic, which has made supply chain firms even more vulnerable to cyberthreats, she says.

What’s made them more vulnerable is the widespread adoption of work-from-home policies designed to curb the spread of the virus, Jazrawy explains. In the past few months, thousands of logistics professionals have migrated from the traditional office to the home office, leaving the safety of the corporate IT infrastructure and logging onto personal laptops using home data networks that are seldom up to date.

“Networks at home don’t have the same firewalls and protection” as at work, Jazrawy says. “You may not have a password on your router. Or you may be using your neighbor’s Wi-Fi, or you haven’t updated Norton Antivirus for three years. So as everybody goes home to work, the hackers are coming. They’re just itching to go; it’s like Christmas for hackers.”

“WE’RE ALL TECH WORKERS NOW”

The supply chain sector has also become more vulnerable to security breaches because fleets today share their data with more partners than ever before in order to provide real-time shipment visibility. “When a customer sends data to a trucking company, a whole chain of data then moves between the dispatcher, planner, loadboards, truck stops, drivers, and more,” Jazrawy says.

As supply chain companies enter the computer age, they need to be aware they are now moving data as well as freight, and criminals see both as valuable targets. “People in the transportation industry don’t think of themselves as technology workers; they don’t think they’re important enough that anyone would want their data,” she says. “But hackers are usually just trying to get their data so they can use it to get even more data and then commit a larger, more profitable crime.”

In order to protect themselves, companies must guard against two types of risk: technological and human. “Most hackers are not so much trying to use technology, but to use social engineering,” Jazrawy says. “If you can get someone to cough up their password, that’s way easier than trying random passwords forever until you get into their system.”

Computer users can defend themselves against those threats by studying the risks and staying vigilant, she says. Most social engineering—or “phishing” attacks—use psychological tactics, preying on fear, greed, or some other human emotion. “So now we’re seeing all these Covid-19 email messages that are playing on fear,” Jazrawy says. “But it’s usually phishing; saying ‘Click here and we’ll solve all your problems.’”

If a transportation worker does click on one of those links by mistake, they should follow two simple steps, she says: First, don’t panic, and second, disconnect from the network—whether it’s a cord or Wi-Fi—and run a virus scan to identify any malware that might have been installed.

Cybercrime in the supply chain sector is definitely on the rise. But across the industry, IT experts agree that there are steps logistics company leaders can take to protect their operations from hackers, including educating employees and putting proper network controls in place. “The more you know and are aware and are vigilant,” Jazrawy says, “[the better your chances of avoiding] the threat.”

Technology
KEYWORDS CarriersEdge Mediterranean Shipping Co. Roadrunner Transportation Systems Toll Group Total Quality Logistics Trimble Transportation truckstop.com
  • Related Articles

    Ryder launches $50 million venture capital fund to back supply chain tech startups

    JDA launches "control tower" software tool to help companies manage supply chain disruptions

    Project44 adds full-truckload data to supply chain visibility tool

Benames
Ben Ames has spent 20 years as a journalist since starting out as a daily newspaper reporter in Pennsylvania in 1995. From 1999 forward, he has focused on business and technology reporting for a number of trade journals, beginning when he joined Design News and Modern Materials Handling magazines. Ames is author of the trail guide "Hiking Massachusetts" and is a graduate of the Columbia School of Journalism.

Recent Articles by Ben Ames

Jungheinrich buys Indiana warehouse automation vendor for $375 million

Shipping groups back bipartisan trucking overhaul bill

Walmart boosts investment in GoLocal delivery-as-a-service platform

You must login or register in order to post a comment.

Report Abusive Comment

Most Popular Articles

  • Outlook 2023: What’s in store for logistics/supply chain?

  • Ports, maritime operators see tide turning as ocean freight tsunami subsides

  • In Person: Steve Beverly of Penske

  • InPerson interview: Rob McKeel of Fortna

  • Shipping groups back bipartisan trucking overhaul bill

Now Playing on DCV-TV

89cfed30 8aac 4284 960d c8c8c1886e16

Have you checked your read rate lately?

DCV-TV 4: Viewer Contributed
No reads. Unaccounted for boxes. Boxes sent to the wrong place. A logistics nightmare! But this nightmare doesn’t have to come true. SICK’s linear line scan camera is what dreams are made of for your logistics operations. And if you’re worried about motion and vibration from conveyor belts...well, there’s no reason...

FEATURED WHITE PAPERS

  • The five best applications for robotic lift trucks in warehouse environments

  • Fulfillment Facility Improved Efficiencies by 4x

  • 3PLs: Complete Orders Faster with Flexible Automation

  • Reusable Packaging for the New Wave of Supply Chain Automation

View More

Subscribe to DC Velocity Magazine

GET YOUR FREE SUBSCRIPTION
  • SUBSCRIBE
  • NEWSLETTERS
  • ADVERTISING
  • CUSTOMER CARE
  • CONTACT
  • ABOUT
  • STAFF
  • PRIVACY POLICY

Copyright ©2023. All Rights ReservedDesign, CMS, Hosting & Web Development :: ePublishing